CVE-2025-0937

Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Policy allowing reads on other namespaces.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:*

History

15 Dec 2025, 21:07

Type Values Removed Values Added
Summary
  • (es) El flujo de eventos de Nomad Community y Nomad Enterprise ("Nomad") configurado con un espacio de nombres comodín puede omitir la política de ACL y permitir lecturas en otros espacios de nombres.
References () https://discuss.hashicorp.com/t/hcsec-2025-02-nomad-vulnerable-to-event-stream-namespace-acl-policy-bypass-through-wildcard-namespace/73191 - () https://discuss.hashicorp.com/t/hcsec-2025-02-nomad-vulnerable-to-event-stream-namespace-acl-policy-bypass-through-wildcard-namespace/73191 - Vendor Advisory
First Time Hashicorp
Hashicorp nomad
CPE cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:*

12 Feb 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-12 19:15

Updated : 2025-12-15 21:07


NVD link : CVE-2025-0937

Mitre link : CVE-2025-0937

CVE.ORG link : CVE-2025-0937


JSON object : View

Products Affected

hashicorp

  • nomad
CWE
CWE-863

Incorrect Authorization